Skip to content
Threat Feed
high advisory

Authentication Bypass in Mooncake Store

Mooncake Store versions through 0.3.13.post1 contain a missing authentication vulnerability in the coro_rpc port, allowing unauthenticated attackers to perform unauthorized deletion operations.

CVE search metadata

CVE search record: CVE-2026-106038. Severity: high. CVSS: 8.2. KEV: no. Product: Mooncake Store (<= 0.3.13.post1). Brief: Authentication Bypass in Mooncake Store. Brief link: https://feed.craftedsignal.io/briefs/2026-10-mooncake-auth-bypass/

Mooncake Store versions up to and including 0.3.13.post1 contain a critical missing authentication vulnerability within its coro_rpc communication component. This flaw permits unauthenticated, remote attackers to interact with internal store management functions. By forging specific requests and setting the force flag, an attacker can bypass intended lease validation mechanisms. This allows for unauthorized execution of administrative operations, specifically the Remove, RemoveByRegex, RemoveAll, and BatchRemove commands. Successful exploitation results in the permanent deletion of arbitrary keys or the complete clearing of the data store, leading to immediate cache loss and sustained service failures for applications relying on the Mooncake Store.

Impact

Successful exploitation of this vulnerability leads to significant data loss and service disruption for environments utilizing Mooncake Store as a caching layer. Attackers can remotely wipe the entire store or selectively target specific keys, which disrupts application operations and forces a loss of cached state. The CVSS 3.1 base score of 8.2 reflects the high impact on availability and the low complexity of the attack, which requires no authentication to execute.

Recommendation

Prioritized actions for security and infrastructure teams:

  • Update Mooncake Store to a version beyond 0.3.13.post1 immediately upon availability of a patch.
  • Implement network-level segmentation to restrict access to the coro_rpc port to trusted internal management hosts only.
  • Monitor ingress traffic on the coro_rpc port for anomalous patterns or unexpected requests containing deletion-related commands.

Immediate actions

Restrict network access to coro_rpc port

IT Operations 24h

Mitigations

Upgrade Mooncake Store to post-0.3.13.post1

immediate IT Operations

CVE-2026-106038